nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #166

Which two of the following standards are used as ISMS third-party certification audit criteria?

The correct answer is D. ISO/IEC 27001 E. Relavent legal, statutory, and regulatory requirements. The two standards that are used as ISMS third-party certification audit criteria are ISO/IEC 27001 and relevant legal, statutory, and regulatory requirements. ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an…

Audit Criteria and Standards

Question

Which two of the following standards are used as ISMS third-party certification audit criteria?

Options

  • AISO/IEC 27002
  • BISO/IEC 20000-1
  • CISO 19011
  • DISO/IEC 27001
  • ERelavent legal, statutory, and regulatory requirements
  • FISO/IEC 17021-1

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    2% (1)
  • D
    89% (55)
  • F
    6% (4)

Explanation

The two standards that are used as ISMS third-party certification audit criteria are ISO/IEC 27001 and relevant legal, statutory, and regulatory requirements. ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS)1. Relevant legal, statutory, and regulatory requirements are those that apply to the organization's information security aspects and objectives2. The other options are either not standards (E) or not directly related to the ISMS certification audit criteria (A, B, C, F).

Topics

#audit criteria#ISO/IEC 27001#certification standards

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice